Skulkin, O.. (2019, January 20). Silence: Dissecting Malicious CHM Files and Performing Forensic Analysis. Retrieved November 17, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.010 Command Obfuscation |
GroupSilence | Silence has used environment variable string substitution for obfuscation. |
| T1053.005 Scheduled Task |
GroupSilence | Silence has used scheduled tasks to stage its operation. |
| T1059.001 PowerShell |
GroupSilence | Silence has used PowerShell to download and execute payloads. |
| T1059.003 Windows Command Shell |
GroupSilence | Silence has used Windows command-line to run commands. |
| T1059.005 Visual Basic |
GroupSilence | Silence has used VBS scripts. |
| T1059.007 JavaScript |
GroupSilence | Silence has used JS scripts. |
| T1070.004 File Deletion |
GroupSilence | Silence has deleted artifacts, including scheduled tasks, communicates files from the C2 and other logs. |
| T1204.002 Malicious File |
GroupSilence | Silence attempts to get users to launch malicious attachments delivered via spearphishing emails. |
| T1218.001 Compiled HTML File |
GroupSilence | Silence has weaponized CHM files in their phishing campaigns. |
| T1566.001 Spearphishing Attachment |
GroupSilence | Silence has sent emails with malicious DOCX, CHM, LNK and ZIP attachments. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.